Or you can mail donations to Henry Shivley at P.O. Box 964, Chiloquin, OR 97624

Equifax CIO, CSO “retire” in wake of huge security breach

Ars Technica – by Cyrus Farivar

On Friday, Equifax announced that two top executives would be retiring in the aftermath of the company’s massive security breach that affected 143 million Americans.

According to a press release, the company said that its Chief Information Officer, David Webb, and Chief Security Officer, Susan Mauldin, would be leaving the company immediately and were being replaced by internal staff. Mark Rohrwasser, who has lead Equifax’s international IT operations, is the company’s new interim CIO. Russ Ayres, who had been a vice president for IT at Equifax, has been named as the company’s new interim CSO.  

The notorious breach was accomplished by exploiting a Web application vulnerability that had been patched in early March 2017.

However, the company’s Friday statement also noted for the first time that Equifax did not actually apply the patch to address the Apache Struts vulnerability (CVE-2017-5638) until after the breach was discovered on July 29, 2017.

As Ars reported earlier in the week, Apache Struts is a framework for developing Java-based apps that run both front-end and back-end Web servers. It is relied on heavily by banks, government agencies, large Internet companies, and Fortune 500 companies. Experian, one of the three big credit reporting services, and annualcreditreport.com, which provides free credit reports, both reportedly rely on Apache Struts as well.

“While Equifax fully understands the intense focus on patching efforts, the company’s review of the facts is still ongoing,” the press release continued. “The company will release additional information when available.”

Cyrus is the Senior Business Editor at Ars Technica, and is also a radio producer and author. His first book, The Internet of Elsewhere, was published in April 2011.


This entry was posted in News. Bookmark the permalink.

3 Responses to Equifax CIO, CSO “retire” in wake of huge security breach

  1. flee says:

    Run…Forrest.. Run…!

    The dike has been breached.

    Let’s plug the leak with a couple of interim stooges to do damage control.

    Run Forrest Run…!

  2. albertpikebishop says:

    gee wiz mommy..have the rats left the boat..i think so..we have too find out where these ceo rats live and if any of us get banged ..we send them the bill..they can run and hide but we will find them..and I have no idea if im involved in this.my credit is excellent..my 3 credit cards..no problems..and I do not do any financial things over the internet..

  3. Mark Schumacher in LV says:

    They had the fix and they didn’t use it. Treason against Americans.


Leave a Reply